Hi Alexander,

In data giovedì, 23 agosto 2012 10.00:18, Alexander Wagner ha scritto:
> For this single record that is in C, right?
> 
> Say:
> 
>     A: allow group "A"
>          recid 1
>          recid 2
>          recid 3
>     B: allow group "B"
>          recid 2
>          recid 3
>          recid 4
> 
>     C: allow "any"
>          recid 3
>          recid 4
> 
> This results in "guest" could see the records 3 and 4 by means of the
> collection C, but not 1 and 2 as they are not member of C. A could see
> 1-4, as 1-3 are members of A and 4 is member of C. B could see 2-4 as
> they are either member of B or C but not 1 which is only in A.

Fully correct!

> > is to relay on FFT$r and set there a firerole rule dynamically
> > generated based on all the complex rules you described...
> 
> Ok. This is what we originally intended as well.

OK, I will try to make soon an extension to this rules to restrict documents 
so that you can combine fireroles/roles etc.

Cheers!
        Sam
--
Samuele Kaplun
Invenio Developer ** <http://invenio-software.org/>

Reply via email to